← Back to blog
Consulting · vendor risk

Vendor risk: assess suppliers without freezing procurement

David
David · COO
Jan 14, 2025 · 1 min read
Sharein𝕏

Questionnaires, SOC 2 evidence, and contract clauses for SaaS and MSP vendors.

Every Puerto Rico SMB depends on dozens of vendors — local MSP, QuickBooks cloud, payroll SaaS, marketing agency with M365 admin access. NIST SP 800-161 guides supply chain risk; enterprise clients ask for TPRM program before signing. Vendor risk assessment must not freeze procurement — tier vendors by criticality and apply proportional rigor.

Tier 1 (prod/PHI/admin access): SIG lite or CAIQ questionnaire, SOC 2 Type II or ISO 27001 evidence, subprocessor review, 72h breach notification clauses, right to audit. Tier 3 (marketing tools without PII): terms review and security page sanity check. Krebs on Security documents breaches starting at small vendor with forgotten access — inventory is step zero.

Want to map this to your real environment?
We help you prioritize controls and risks before they become incidents.
Request assessment →

Contracts: DPA for GDPR/CCPA where applicable, negotiated liability cap, data residency disclosure. Carolina MSP with admin in their tenant must document client segregation. Bruce Schneier recommends least privilege extended to vendors — temporary, logged, quarterly reviewed access.

Automate where possible: minimum viable centralized spreadsheet; Vanta/Drata for scale. Offboarding checklist when canceling vendor — revoke OAuth, change shared passwords, remove Azure AD guest accounts. Shadow IT SaaS discovered in audit is unmanaged vendor risk.

Puerto Rico companies serving mainland clients must align TPRM to client expectations — questionnaire answered honestly with remediation plan beats lying checkbox. Vendor risk is marathon; start with top 5 critical vendors this quarter.

vendor riskthird partyTPRMproveedoresassessmentNIST
David
David
COO, WW Cyberware Solutions

Operations and execution — connecting strategy with what the team ships every week.